Published September 12, 2026 — Memphis, Tennessee. Sedgwick confirmed a cyberattack on a subsidiary that operates a file transfer system servicing government agencies, disclosed via SecurityWeek on September 12, 2026. The attack compromises a file transfer system used by Sedgwick's subsidiary to exchange files with government clients. The affected countries include the United Kingdom, Germany, France, Italy, Spain, Netherlands, Belgium, and Poland.
Data last verified September 12, 2026 from SecurityWeek's coverage of the Sedgwick cyberattack (September 12, 2026), OffSeq Threat Radar incident analysis, and Sedgwick company information.
Quick Answer
Sedgwick confirmed a cyberattack on a subsidiary operating a file transfer system for government agencies (disclosed September 12, 2026 via SecurityWeek). Specific technical details about the attack vector, malware, or exploitation methods have not been publicly disclosed. The compromise of a file transfer system serving government agencies indicates a significant breach of confidentiality and potential disruption of data availability. Affected countries: United Kingdom, Germany, France, Italy, Spain, Netherlands, Belgium, and Poland. Severity: medium-to-high. Organizations using managed file transfer (MFT) systems should audit their systems, patch known vulnerabilities, and rotate credentials (SecurityWeek, September 12, 2026; OffSeq Threat Radar, September 12, 2026).
What we know about the Sedgwick cyberattack
| Detail | Information |
|---|---|
| Victim | Sedgwick subsidiary (file transfer system for government) |
| Disclosed | September 12, 2026 |
| Reporting source | SecurityWeek, citing Sedgwick disclosure |
| Attack vector | Not publicly disclosed |
| Malware | Not publicly disclosed |
| Threat actor | Not publicly attributed |
| Data accessed | Government-client file transfer contents |
| Affected countries | UK, Germany, France, Italy, Spain, Netherlands, Belgium, Poland |
| Severity | Medium-to-high (per OffSeq analysis) |
Source: OffSeq Threat Radar (September 12, 2026); SecurityWeek (September 12, 2026).
About Sedgwick
Sedgwick is a global leader in claims management, loss adjusting, and risk services. Key facts:
- Headquarters: Memphis, Tennessee, USA.
- Employees: 33,000+ across 80 countries.
- Clients: Commercial insurance carriers, employers, government agencies, and third-party administrators.
- Services: Claims management, loss adjusting, managed care, fraud investigation, risk consulting, and absence management.
- Data handled: Medical records, financial information, personally identifiable information (PII), insurance claims, and government records.
The company's subsidiary that operates the file transfer system handles confidential exchanges with government agencies across Europe — making this attack particularly sensitive from a data-protection standpoint (Sedgwick, 2026).
File transfer systems: a frequent attack target
Managed File Transfer (MFT) systems have been among the most-attacked enterprise platforms in recent years. Notable MFT breaches and vulnerabilities:
| Year | MFT platform | CVE / Incident | Impact |
|---|---|---|---|
| 2020-21 | Accellion FTA | CVE-2021-27102 et al. | 100+ organizations, including Shell, Qualys, Bombardier |
| 2023 | GoAnywhere MFT | CVE-2023-0669 | Cl0p ransomware, 130+ organizations |
| 2023 | MOVEit Transfer | CVE-2023-34362 | Cl0p ransomware, 2,000+ organizations, ~$1B in damages |
| 2024 | Various MFT | CVE-2024-XXXX (multiple) | Targeted ransomware campaigns |
| 2026 | Sedgwick MFT subsidiary | Sedgwick cyberattack (Sep 12) | 8 European countries affected |
Source: SecurityWeek, OffSeq Threat Radar (2020-2026); CISA advisories.
MFT platforms are attractive targets for ransomware groups and nation-state actors because they:
- Hold sensitive data in transit between organizations
- Have elevated network permissions and integration access
- Are often accessible from the internet for partner exchanges
- Historically have had unpatched vulnerabilities (especially older versions)
- Are sometimes overlooked in patch management programs
Why MFT attacks matter for government agencies
When an MFT system serving government agencies is compromised, the impact extends well beyond the immediate operator. Government data handled through MFT systems often includes:
- Citizen data: Tax records, benefits applications, immigration documents, social services records.
- Healthcare data: Medicaid claims, public health records, vaccination data (protected by HIPAA in the US, GDPR Article 9 in the EU).
- Criminal justice data: Police reports, court records, corrections data.
- Tax and financial data: Government revenue data, contract awards, vendor records.
- Defense-related data: Procurement, personnel, operational records.
The Sedgwick breach, affecting 8 European countries, may trigger GDPR breach notification requirements (Article 33 - notify supervisory authority within 72 hours; Article 34 - notify affected individuals when high risk). National cybersecurity agencies in the UK (NCSC), Germany (BSI), France (ANSSI), Italy (ACN), Spain (CCN), Netherlands (NCSC-NL), Belgium (CCB), and Poland (CERT Polska) are likely involved in the response (GDPR, 2016; OffSeq Threat Radar, September 12, 2026).
Defensive recommendations for MFT users and operators
Organizations using MFT systems — either as operators or as consumers exchanging files via MFT — should take the following actions:
- Inventory all MFT systems across your environment, including third-party MFT providers you exchange files with.
- Patch to the latest version of your MFT software. Apply security updates within 7 days of release.
- Audit MFT logs for the past 90 days. Look for unexpected admin access, large file downloads, and unfamiliar IP addresses.
- Rotate credentials for all MFT admin accounts and integration partners.
- Enable multi-factor authentication for all MFT admin access.
- Implement network segmentation - MFT systems should not have direct internet access without a VPN or zero-trust gateway.
- Enable detailed audit logging and integrate with SIEM for real-time alerting on suspicious activity.
- Review data exchange policies - ensure only minimum necessary data is exchanged via MFT.
- Verify your MFT provider's security posture - request SOC 2 Type II reports, ISO 27001 certification, and incident history.
- Review file encryption - ensure files are encrypted in transit (TLS 1.2+) and at rest on the MFT server.
What to expect from Sedgwick's response
Following standard incident response protocols, Sedgwick will likely:
- Notify affected government clients in each of the 8 affected countries within the GDPR-mandated 72-hour window.
- Engage external cybersecurity firms for forensic investigation.
- Report to data protection authorities in each affected country (ICO in the UK, CNIL in France, etc.).
- Provide credit monitoring or identity protection if personal data was exposed.
- Implement additional security controls to prevent reoccurrence.
- Update incident response plans based on lessons learned.
Sedgwick's customers should expect direct notification from the company if their data was potentially affected (Sedgwick, 2026; SecurityWeek, September 12, 2026).
FAQ
Is Sedgwick the same as Sedgwick Claims Management Services?
Yes. Sedgwick International (parent) operates through regional subsidiaries including Sedgwick Claims Management Services, Inc. (US), and various European entities. The file transfer system affected by the September 12, 2026 attack is operated by a European subsidiary (Sedgwick, 2026).
What is the financial impact of the Sedgwick cyberattack?
Financial impact has not been publicly disclosed. Incident response costs (forensics, legal, notification, remediation) for similar breaches typically range from $1M-$10M for mid-sized enterprises. Larger breaches can exceed $100M when factoring regulatory fines, litigation, and reputational impact (IBM Cost of a Data Breach Report, 2026).
Should I be concerned if my organization uses Sedgwick for claims processing?
If you use Sedgwick for claims processing, you may have file exchanges through the affected subsidiary's MFT system. Watch for direct notifications from Sedgwick about data exposure. In the meantime, audit your own systems for any third-party file transfers from Sedgwick in the past 90 days, and rotate any credentials used for those exchanges (Sedgwick, 2026).
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









